Last year 48,064 people over sixty reported a phishing or spoofing scam to the FBI. It was the single most common crime reported by that age group, more than double the next one on the list. Across every category of fraud, Americans over sixty reported losing $7.75 billion, up 59% in a single year, and 12,444 of them lost more than $100,000 each. That is not a rounding error in somebody’s retirement. That is the retirement.
Here is how it goes: An email arrives and it looks exactly like the ones grandpa’s bank has sent for years. Same logo, same typeface, same slightly stiff phrasing. There is a problem with a recent transfer and he needs to confirm a few details. The link opens a page that also looks exactly right, so he types in what it asks for, because that is plainly what the page is for. By the time anyone notices something’s wrong, that money is long gone.
Here is the part I keep turning over: His phone has an AI on it. It has had one for a while, and this month it got considerably better. It can summarize that email and draft a reply to it. It could, in principle, check whether he has ever received mail from that domain before, notice that the link text and the link destination don’t match, glance at his recent transfers, and put those things together faster than any human being could.
It just was not built to care.
I have been thinking about this since I read “An Alien Mind,” the essay OpenAI’s chief scientist Jakub Pachocki published a few weeks ago and that Sam Altman went out of his way to call important. The argument running through it, and through most of what gets written about AI right now, is that these systems are becoming powerful in ways we don’t fully understand, and that the far end of that curve is genuinely frightening — engineered pathogens, autonomous agents operating at scale, capabilities that a small number of people could point at a very large number of people. I think that is true; this is not a piece about how the worriers are wrong. Pachocki writes that we need to “preserve human agency and enshrine an intrinsic value to being human, in a world where most tasks could be performed by AI,” and I agree with that as well.
It is a piece about the sentence that never comes next.
Because if we accept the premise — if AI really is about to become capable enough to help somebody build a weapon that kills thousands of people — then we have also just accepted that AI is getting capable enough to notice one. Not automatically, and not as easily — an attacker needs one opening to work and a defender has to be right over and over, which is a real asymmetry and not a small one. But that capability is coming off the same curve. And we are spending almost none of our public imagination on the second half of it.
So I think the defining question of the next five years is who these systems are pointed at protecting. Not just how powerful they get. We have that conversation constantly, and lately it is the only one we are having.
The image I can’t shake is a bodyguard — an actual person, walking a few feet ahead, scanning a room that the person he’s protecting isn’t looking at. The president has a detail. Their entire job is to watch the space around someone who’s busy living their life. Most of what they do is nothing, right up until it isn’t.
Almost nobody else can afford that. But AI is democratizing LOTS of things that the internet revolution started to democratize.
I want to be clear that I am not complaining about what the technology can do today, because today is the worst it will ever be. Altman is building a device with Jony Ive that is meant to sit in a room and pay attention; the first one is reportedly a speaker with a camera, arriving sometime in 2027. Ask me what something like that could do three years after that and “summarize my email” is not the interesting answer. Meanwhile researchers at Tufts have printed biological sensors onto fabric and gloves and masks, sensors that glow when they encounter a pathogen or a toxin. Put those two trajectories in the same room and you get something that could tell you the air in here is wrong before you feel it. Those seconds could be enough to save your life.
There is a lab sequencing the wastewater of two dozen American cities carefully enough to spot a single case of measles. There are AI systems reading source code and finding the flaws that attackers were about to use, before they used them. There are fraud models watching hundreds of millions of transactions a day, trained on patterns no human analyst could hold in their head. All of that is running today, and getting better.
So what about the systems that work for US? The ones that aren’t built to make money, but are built to protect us from systems built by people who make money. The ones that work for us and are tuned and aligned to our needs above everything else. The AI that:
- Watches your technology for threats, risks, intrusions, and decides what it can block for you and what it needs to alert you about;
- Scans the air, the water, the food entering your mouth to ensure it isn’t going to hurt you;
- Keeps track of all the signals of security risks around you like local crime reports, sounds, other people’s devices, and the time of day to recommend you immediately share your location with your family and call a friend while you move quickly to the nearest secure location?
Part of the problem is that some of these pieces exist and are coming together, but most people are not going to assemble them into a coherent system. You can already buy things like child-tracking software, or figure out a way to get an AI to scan your email but putting all those pieces into one bodyguard system is something 99% of the world will never do.
So why hasn’t anybody built it? I think there are three reasons, and none of them are technical.
The first is that protection is hard to sell, and much harder to sell voluntarily. That sounds wrong at first, because plenty of things do sell avoided harm: smoke detectors, airbags, antivirus, insurance. But look at why people actually own those. Smoke detectors are in your house because building code puts them there. Airbags are in your car because of a federal rule. Insurance gets bought because a lender or a state requires it. The prevention products that succeed on their own tend to be the ones where the mechanism is cheap and obvious enough that you can see it working: a lock, a seatbelt.
A bodyguard is neither of those. It’s expensive, its whole value is a counterfactual, and you can never confirm that the thing it stopped would really have happened. The closest voluntary version we have is identity-theft protection, which is a genuine market and a famously mediocre product — sold on fear, heavy on churn, thin on anything you could point to. That’s what this thing is up against. Every productivity feature gets a clean pitch: here’s the thing, here’s the two hours a week it hands back to you. Nothing happened is a harder pitch, and nobody is writing it into building code.
The second is that the companies building the pieces are selling them upstream. There’s a startup called Charm Security that raised $8 million to build what they call an agentic AI workforce for scams and human-centric fraud. It assesses how vulnerable a given person is to social engineering, watches for the patterns, and steps in while it’s happening. It won Best Technological Solution at this year’s Global Anti-Scam Summit in Europe. It is, almost exactly, the thing I’ve been describing – but it’s sold to banks.
And the reason is arithmetic. The bank has the money, the bank has the transaction data, and the bank eats the liability when things go wrong. So the protection reaches grandpa as a side effect of protecting someone else’s balance sheet — which is fine, right up until the moment his interests and the bank’s point in different directions, and then we all know which way that goes.
It was the same everywhere I looked: A lab reporting pathogen signals to public health agencies, AI systems handing vulnerability reports to software maintainers, fraud models answering to the institution that trained them. All of it real, all of it working, all of it accountable to somebody with a legal department. The protection is being built. It’s just being pointed over your head.
The third reason is the honest one, and it’s about access. To actually do this job, a bodyguard has to see everything: your mail, your calls, your calendar, your money, your location, who’s standing near you. That’s what makes the work possible. It’s also a precise description of the most invasive thing you could install in a person’s life. The system that would protect your grandfather is architecturally identical to the one his children would use to control him.
Apple and Google are never handing that level of access to a third party, because it’s the one thing they keep. Which means the only two outfits positioned to assemble the bodyguard are the two whose entire business model is the productivity assistant. That’s the trap. That’s why the pieces sit there in a pile.
But I don’t think the surveillance problem is fatal, and the answer to it is about three thousand years old: Odysseus wanted to hear the Sirens sing. He also knew that everyone who heard them steered into the rocks. So before he got anywhere near them he had his crew tie him to the mast, plug their own ears with wax, and — this is the part that matters — ordered them in advance to ignore anything he said while he was under the spell. He got the thing he wanted without the thing that comes with it, by binding his future self at a moment when he was still thinking clearly.
Philosophers call it precommitment, and you already live inside half a dozen of them. An advance medical directive is you telling a future, less competent version of yourself what he’s allowed to decide. A gambling self-exclusion list is you putting your own name on a roster the casino is legally obligated to enforce against you. Automatic 401k escalation is you spending a raise you haven’t gotten yet.
That’s the whole difference between a bodyguard and a guardian. A guardian substitutes its judgment for yours. A bodyguard enforces your own instruction against a version of you that somebody is actively working on. The authority runs from you. Nobody appointed it, and nobody can hand it to your kids.
And the design answer is a delay rather than a lock.
Look at what the numbers actually say. Phishing was the most commonly reported crime among people over sixty last year by a wide margin, 48,064 reports, and it comes twelfth in money, at $77 million. Investment fraud was reported a third as often and took $3.5 billion. Those are two completely different problems filed under the same heading. The first is pattern matching, and a machine is already better at it than any of us are. The second unfolds over weeks, with the victim’s enthusiastic cooperation, and not one individual transaction in it looks wrong.
You don’t catch the second one. You slow it down.
Every scam that takes real money runs on manufactured urgency: the account closes today, the opportunity closes tonight, don’t tell your family because they won’t understand. A rule you wrote for yourself on a calm Tuesday — nothing over five thousand dollars to a new recipient inside twenty-four hours — costs you almost nothing, because legitimate money almost never has to move in the next thirty minutes. And it defeats nearly the entire category.
We know it works, because we already do it to people without asking them first. Every state in the country has adopted some version of a model law letting a brokerage delay a disbursement from an older adult’s account for up to fifteen business days on suspicion of exploitation, extendable by another ten. It’s a genuine protection and it stops genuine theft. It also applies to you because you had a birthday, it was written by somebody else, and you cannot override it. People resent it for exactly those reasons.
Same mechanism, completely different thing. One is a rule about you. The other is a rule you wrote.
There is at least one person in Washington trying to solve the loyalty problem with law instead of engineering. Senator Mark Warner put out a discussion draft in June of something called the AI AGENT Act, and formally introduced it on July 21st as S. 5051. It does a thing I haven’t seen anywhere else: it creates a legal category for an AI that works for you. A “custodial user agent,” in the bill’s language, is software you have explicitly authorized to act on your behalf, carrying the same legal standing you do. Its provider picks up duties that cannot be waived — safeguard your data, avoid self-dealing, avoid foreseeable harm, follow your instructions, keep records you can actually audit — and is flatly barred from using anything it learns while working for you for advertising or profiling or resale. Non-waivable is the word that matters: no terms-of-service checkbox signs it away. Warner had made the principle explicit a few weeks earlier, in a June letter to the Treasury Secretary: AI agents, he wrote, “especially in the financial services context — should owe a duty of loyalty to the principal on whose behalf they are acting, like that of other fiduciaries.”
Which is the thing I have been circling this whole time, finally written down: loyalty is a legal status, not a model property. You can’t train it in. You can only owe it.
I don’t want to oversell the bill, though. Ellen Goodman at Tech Policy Press wrote the sharpest response I’ve read, and she is supportive without being sentimental about the holes: we have no reliable way to verify that an agent is behaving loyally, because these systems operate over long stretches without anyone specifying their behavior in advance and there’s no accepted standard for auditing what a model did or why. “Best interest” turns slippery the moment a person’s interests conflict with each other, which is most of the time. And the bill hands enforcement to an FTC currently standing on considerably less independent ground than the drafters would like. A duty you cannot measure is a duty that is hard to enforce.
It also isn’t a new idea, which is the part that nags at me: Consumer Reports has been arguing for what they call loyalty by design since October 2024 — personal agents that advocate for the consumer, bound by a duty of loyalty, grounded in electronic-agent law that has been on the books in nearly every state since 1999. They named their obstacles clearly — credential-sharing risk, liability ambiguity, no protocol standard — and two years later all three obstacles are still standing, and so is the absence of the product.
Then there’s the problem I can’t resolve, which I’ll just put on the table. If a bodyguard has to see everything about you, you need some way to verify it isn’t reporting home, which argues for open weights running locally on hardware you own: that’s the only arrangement where “it sees everything” doesn’t also mean “a company sees everything.” But an open defender is a defender your attacker can download, run on his own machine, and practice against until his message gets through. Closed systems get to keep secrets. Open ones get to be trusted. I don’t know how to have both, and I notice that nobody selling me anything has admitted the tradeoff is there.
And a bodyguard is itself a door. AI Now published a paper this summer on defensive cyber agents being hijacked into executing an attacker’s code: the guard turned around and pointed at the person it was guarding. Anything you hand that much access to becomes worth attacking precisely because you handed it that much access.
None of which makes me think we shouldn’t build it. It makes me think we aren’t even arguing about it yet.
Because here is what I keep coming back to: every hard problem in this piece is a design problem or a legal problem, and not one of them is a capability problem. We know how to spot a phishing page. We know how to delay a wire transfer. We know how to write a duty of loyalty — lawyers have been drafting them for centuries, for doctors and trustees, all of whom see everything about you and are bound by what they owe you. The pieces are sitting on the table. And the same capability curve that has everyone frightened is the curve that ends with somebody’s grandfather having a detail: a thing that watches the space around him while he goes about his life, that mostly does nothing, right up until the morning an email arrives that looks exactly like his bank.
We are going to spend this entire decade arguing about how dangerous the thing at the end of that curve is. I would like us to spend some of it deciding who it’s standing next to.
Sources
- Jakub Pachocki, “An Alien Mind”, OpenAI, September 6, 2026
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report — elder fraud figures, pp. 44–46
- SecureBio Detection, August 2026 update — CASPER wastewater sequencing
- Google DeepMind, CodeMender
- Charm Security
- NASAA, Model Act to Protect Vulnerable Adults from Financial Exploitation
- Sen. Mark Warner, AI AGENT Act discussion draft (June 29, 2026), introduced as S. 5051 on July 21, 2026
- Sen. Mark Warner, letter to the Treasury Secretary on agentic AI, June 2, 2026
- Ellen P. Goodman, “Senator Warner Makes a First Foray into Agentic AI Regulation”, Tech Policy Press, July 13, 2026
- Consumer Reports Innovation Lab, “Empowering Consumers with Personal AI Agents”, October 2024
- Boyan Milanov and Heidy Khlaaf, “Friendly Fire: Hijacking Defensive Cyber AI Agents for Remote Code Execution”, AI Now Institute, July 2026
- Tufts University, printable biopolymer sensors that detect pathogens and toxins, 2023
